AI governance for banks and financial services
In financial services, the AI Act is neither the only reference nor the first one in place. It builds on an existing supervisory framework, and the challenge is not understanding each rule in isolation but making overlapping obligations work across different processes.
The regulatory framework
- AI Act, Annex III: assessment of the creditworthiness of natural persons is classified as high risk, with obligations applying from 2 December 2027 following the Digital Omnibus postponement
- DORA, for digital operational resilience and the management of critical third-party providers
- EBA guidelines on internal governance and model risk management
- GDPR, for automated decisions that produce legal effects on individuals
- ISO/IEC 42001, as a voluntary method for bringing the preceding requirements together
Use cases and their risk level
| Use case | Classification | Note |
|---|---|---|
| Credit scoring of natural persons | High risk, Annex III | Full obligations for data, documentation and human oversight |
| Anti-money laundering and fraud detection | Assess case by case | Depends on purpose and impact on the individual |
| Customer-facing conversational assistants | Limited risk | Article 50 transparency obligations, already in force |
| Market risk models | Outside Annex III | Existing prudential requirements still apply |
| Internal productivity tools | Minimal risk | They should still be included in the inventory |
Where to start
- 1Build an AI system inventory based on purpose rather than tool, because the same model used in two processes can have two different classifications
- 2Verify the role assumed for each system, provider or deployer: fine-tuning on proprietary data may place the bank among providers under Article 25
- 3Align existing model risk management with AI Act requirements instead of building a second parallel framework
What we do for the sector
The path is always the same and the content changes: it starts from the use case map, assesses impact before investing, validates with a prototype, and only then reaches production. Rapid prototyping runs through protot.ai, our validation unit.
Use case definition
We map the processes where AI produces value and those where it only adds risk, distinguishing by purpose rather than by tool: the same model used in loan processing and in marketing campaigns carries two different classifications. The output is a prioritised use case portfolio, each with its risk class and the role the bank assumes.
Impact assessment
For every use case in the portfolio we measure expected economic impact and impact on people, which for Annex III systems is also a regulatory obligation. The Value Case always compares the AI option against the non-AI alternative, and when the latter wins we say so.
Prototyping and validation
With protot.ai we build a working prototype on real data within weeks, to test the hypothesis before committing project budget. In credit, that means testing against a historical sample whether the model meets acceptance thresholds defined beforehand rather than afterwards.
Production and oversight
When the prototype confirms the hypothesis we support the move to production: integration with portfolio systems, event logging consistent with Article 12, human oversight designed in rather than bolted on, technical documentation. Then ongoing oversight remains, because a model whose behaviour shifts needs reassessment.